Exit demo CSP-ASSESSOR Customer Security Programme Assessor PDF format · free preview

Swift CSP-ASSESSOR - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/csp-assessor.html

Question 1
Single choice

A Treasury Management System (TMS) application is installed on the same machine as the customer connector (such as MQ server) connecting towards a Service Bureau Are these applications/systems in scope of CSCF?

A.

The TMS application, the MQ server and hosting system are in the scope of the CSCF and must be placed in a secure zone

B.

The TMS application, the MQ server and hosting system enters the scope of the CSCF advisory and should be placed in a secure zone

C.

Only the MO server application is in scope of the CSCF> The TMS application is considered as back-
office

D.

The TMS application is the highest risk and must be secured appropriately. The MQ server should be secured on a best effort basis

Question 2
Single choice

The SWIFT HSM Box must be hardened at the system level by the SWIFT user owning the equipment.

Swift Customer Security Controls Policy

Swift Customer Security Controls Framework v2025 Independent Assessment Framework

Independent Assessment Process for Assessors Guidelines

Independent Assessment Framework - High-Level Test Plan Guidelines

Outsourcing Agents - Security Requirements Baseline v2025

CSP Architecture Type - Decision tree

CSP_controls_matrix_and_high_test_plan_2025

Assessment template for Mandatory controls

Assessment template for Advisory controls

CSCF Assessment Completion Letter

Swift_CSP_Assessment_Report_Template

A.

TRUE

B.

FALSE

Question 3
Multiple choice

Select the correct statement(s).

A.

The public and private keys of a Swift certificate are stored on the Hardware Security Module

B.

The certificate stored on the Swift Hardware Security Module is used during the decryption operation of a message

C.

The decryption operation uses the encryption private key of the receiver

D.

To verify the signature the SwiftNetLink uses the signing private key of the receiver

Question 4
Multiple choice

For which reasons (as per the "CSP Independent Assessment Process for Assessors Guidelines") is it required to keep minutes of all key meetings related to a CSP assessment process (examples: kick-off, scope definition, exit meeting)? (Select all answers that apply)

Swift Customer Security Controls Policy

Swift Customer Security Controls Framework v2025

Independent Assessment Framework

Independent Assessment Process for Assessors Guidelines

Independent Assessment Framework - High-Level Test Plan Guidelines

Outsourcing Agents - Security Requirements Baseline v2025

CSP Architecture Type - Decision tree

CSP_controls_matrix_and_high_test_plan_2025

Assessment template for Mandatory controls

Assessment template for Advisory controls

CSCF Assessment Completion Letter

Swift_CSP_Assessment_Report_Template

A.

To support quality review (audit) processes

B.

For documentation purpose

C.

To keep key information that can be used as input for the next step in the assessment process

D.

To be uploaded in KYC-SA at the end of the assessment (mandated by SWIFT)

Question 5
Single choice

A SWIFT user owns a customer connector and a communication interface. What architecture type is the SWIFT user? (Select the correct answer)

Swift Customer Security Controls Policy

Swift Customer Security Controls Framework v2025

Independent Assessment Framework

Independent Assessment Process for Assessors Guidelines

Independent Assessment Framework - High-Level Test Plan Guidelines

Outsourcing Agents - Security Requirements Baseline v2025

CSP Architecture Type - Decision tree

CSP_controls_matrix_and_high_test_plan_2025

Assessment template for Mandatory controls

Assessment template for Advisory controls

CSCF Assessment Completion Letter

Swift_CSP_Assessment_Report_Template

A.

A1

B.

A2

C.

A3

D.

A4

Question 6
Single choice

The SWIFT VPN boxes are located between the Messaging and Communication interface.

Connectivity

Generic

Products Cloud

Products OnPrem

Security

A.

TRUE

B.

FALSE

Question 7
Multiple choice

A Swift user uses an application integrating a sFTP client to push files to a service bureau sFTP server
What architecture type is the Swift user?
(Choose all that apply.)

A.

A1

B.

B

C.

A3

D.

A4

Question 8
Multiple choice

What is expected regarding Token Management when (physical or software-based) tokens are used? (Choose all that apply.)

A.

Similar to user accounts, individual assignment and ownership for accurate traceability and revocation in case of potential tampering, loss or in case of user role change

B.

Have in place a strict token assignment process. This avoids the need to perform g a regular review of assigned tokens

C.

Individuals must not share their tokens. Tokens must remain under the control and supervision of its owner

D.

All tokens must be stored in a safe when not used

Question 9
Single choice

The Swift user would like to perform their CSP assessment in May for the CSCF version that will only be active as from July the same year.
Is it allowed?

A.

No, an assessment can only be done on the active version of the CSCF

B.

Yes, the assessment on a particular version can start before the actual activation date

Question 10
Single choice

The SwiftNet Link (SNL) software is always required for the Swift Alliance Gateway to operate.

Connectivity

Generic

Products Cloud

Products OnPrem

Security

A.

TRUE

B.

FALSE

Showing 10 of 116 questions · Unlock the full set